February 12, 2026

Tugboat Changelog

v2.26.6

In This Release...

  • Beefed up our Content-Security-Policy headers with additional directives, further hardening the dashboard against cross-site scripting and injection attacks.
  • Fixed a bug where closing a window could knock out real-time updates for all your connected browser tabs. If you ever noticed service states going stale and had to do a full page refresh — that was this guy. Squashed!
  • Added logging for successful and failed login and logout events to improve authentication auditing and security visibility.
  • Added Subresource Integrity (SRI) hashes to externally-hosted stylesheets, so your browser can verify they haven't been tampered with before loading them.

Recent Releases

v2.26.36
August 7, 2026
Git provider refs are now searchable for those refs not on a given page, and we introduced some web server hardening.
v2.26.35
August 3, 2026
Project admins now get notified when scheduled Base Preview refreshes fail, keeping everyone informed.
v2.26.34
July 28, 2026
Fixed an over-restrictive CSP policy blocking Lighthouse score pages.
v2.26.33
July 23, 2026
Bumped dependencies across the stack.
v2.26.32
July 16, 2026
Tightened CORS policy and bumped dependencies across the board.
View All